Data Deletion

Proper and timely deletion of personal data is a fundamental part of data protection compliance. Incomplete or inconsistent deletion processes can create legal risks and undermine trust.

Our Support for You

We analyse your data retention and deletion processes and assess whether they comply with applicable legal requirements. We help you implement effective deletion strategies, from automated deletion rules to documented procedures, ensuring that personal data is removed securely and in line with regulations.

Our support is practice-oriented, tailored to your industry and specific processes, and ensures that data deletion becomes a reliable part of your overall data protection management.

Compliance Requirements

The core obligations of the GDPR: an overview of the fundamental requirements for your company.

Data Protection Management

A clear structure and defined responsibilities are the foundation of any sustainably successful data protection management. We help you to embed data protection principles within your company, establish clear accountabilities, and foster a lasting data protection culture through policies and training.

How we support you:

  • Establishing clear data protection roles
  • Developing internal policies
  • onducting practical training sessions

Documentation and Accountability

The extensive documentation and accountability obligations are the basis for robust and sustainable data protection compliance. In particular, a meaningful Record of Processing Activities (“ROPA”) is fundamental for assessing risks and for providing information to supervisory authorities.


How we support you:

  • Creating and structuring of the ROPA
  • Reviewing existing documentation
  • Continuous maintenance and updating

Legal Bases

The lawfulness of data processing requires an applicable legal basis. We support you in the precise identification and robust documentation of this crucial compliance prerequisite.

How we support you:

  • Reviewing identified legal bases
  • Advising on specific questions, e.g., regarding legitimate interests
  • Support in handling consent matters

Data Transfers

Whether it's data processing agreements, intra-group data flows, or international transfers, we support you in meeting the complex legal requirements and advise you on identifying and minimising data protection risks.

How we support you:

  • Advice on data protection structuring
  • Reviewing documents and contracts (e.g., DPAs, SCCs, DTIAs)
  • Information on current legal developments (i.e., for third-country transfers)

Information and Transparency

Transparency is a cornerstone of the GDPR. You must inform data subjects clearly and comprehensibly about the processing of their data (e.g., through privacy notices).

How we support you:

  • Drafting and reviewing privacy notices
  • Ensuring information obligations are met
  • Advice on transparent communication

Data Subject Rights

The GDPR grants data subjects extensive rights regarding their personal data (e.g., access, deletion). Handling data subject requests efficiently, timely and in compliance with all legal requirements, including current judgements, is essential.

How we support you:

  • Implementing processes for fulfilling data subject rights
  • Drafting response letters
  • Support with complex requests

Data Security and Risk Management

The protection of personal data requires appropriate technical and organisational measures (“TOM”). A comprehensive risk assessment and, where necessary, a Data Protection Impact Assessment (“DPIA”) help to identify and implement suitable measures.

How we support you:

  • Assessing the adequacy of TOM
  • Support with risk assessments
  • Guidance on Data Protection Impact Assessments

Data Protection Incidents

Despite all precautions, incidents that qualify as data breaches can occur. Swift and comprehensive action, while adhering to notification deadlines for supervisory authorities and data subjects, is crucial to limit further adverse effects.

How we support you:

  • Developing a data breach management process
  • Support in assessing incidents
  • Guidance during the supervisory authority notification process

Deletion and Retention

Personal data may only be stored for as long as is necessary for the purpose or as required by statutory retention periods. A structured deletion concept is therefore essential.

How we support you:

  • Developing deletion concepts
  • Advice on data minimisation
  • Support with processes for implementing the deletion concept

Not what you were after?

Reach out to us.

OC Services GmbH, Innere Kanalstraße 15, 50823 Cologne, Germany
Registration Court: Local Court of Cologne, HRB 92393
Managing Director: Gereon Abendroth, Nicolas Gabrysch-Wolff, Dr Marc Störing
Language: